cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>
- To: Eleanor Coultish <eleanor.coultish AT york.ac.uk>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: Re: [[cat-users]] Onboarding/setup ssid
- Date: Wed, 24 Aug 2022 15:50:33 +0000
- Accept-language: en-GB, en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eD5KgcVDWkLMDEpOhOxRiqbMMw+Ol5ce6kDYroODOLM=; b=ToBqZdeO/+OCaRQ6qAq5FxBgzRbejtzrU3gM73jRXBd+n3JYVETdKvzyd53sGyKtWX1pBhh76uH3fBxGip1r+TRYDA6QeZk80VQK5wT0L/0albEsdTDEqEKCN0dM/AiYDIQP+7vULRI1Qs/a0bGkrMvhYWbbZaqc6pn0vMjM5nLesT3/YhN2dDbxDxlgpd//gyJhAqna+q9+Xwi9PRdNLyO7NWeqX6wfZyaTYPOHoeo+vYfUHDp0aIzuraA1u/IFIMqSsb6I6zsuM1GQY6brGLXk2scVFB5gkj3EhhvMCK89ock2vOUzdBeWaWtW2k+GBqv6MZwnzK72UHEpxDdrbQ==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FQQQntDKKSJ/7BjBvF93QpwYfUegMV68gbNCLK4xLtJhbLgZsmOAHgPiEUZwPJ4Okk4Iofc2JmVXSNjbwhbP5rGj+n624C+n/w3g6zGv2Uv3w67nFPQdYllRFMiI7aMtu6naW6Y94z/pjnEZxREyZazJQSTbQOcTGgn/fr5mCmlEJ0cX/vrJMfR1SszydvvJujCEwqStpg07RZGj0xCPuf/DlXhyHvBa0RQlU5PeG/H9pabgS/liyvNdj1/OzFsYpzUvb4Bp6F3O5h0Xi2Okmp7xSbC9/wRUIpQO6T0LN7W3M4OL2KRTuM4Vkyd9MiY8/SVnBUpPu+epYYuL30c0zw==
- Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=jisc.ac.uk;
Hi Eleanor,
Apologies – I just saw this email. You mentioned a Jisc mailing list – can you tell me which list that is? I’m concerned I’ve missed something here. As for the on-boarding SSID, we’ve found that the old traditional CAT site is easy to deal with, but a tool like geteduroam would need somewhat more (given some of its back-end infrastructure is based in the cloud). A year or two ago, we had this query from Uni Cardiff, and I ran a DNS capture to see which hosts would be accessed when attempting to use iOS and Android devices for Google Play, Apple AppStore and subsequently geteduroam. This is what I have from that experiment.
query[A] 19-courier.push.apple.com from 192.168.4.11 query[A] 21-courier.push.apple.com from 192.168.4.11 query[A] 44-courier.push.apple.com from 192.168.4.11 query[A] api.smoot.apple.com from 192.168.4.11 query[A] bag.itunes.apple.com from 192.168.4.11 query[A] buy.itunes.apple.com from 192.168.4.11 query[A] captive.apple.com from 192.168.4.11 query[A] cat.eduroam.org from 192.168.4.11 query[A] cf.iadsdk.apple.com from 192.168.4.11 query[A] cl2.apple.com from 192.168.4.11 query[A] cl3.apple.com from 192.168.4.11 query[A] cl4.apple.com from 192.168.4.11 query[A] cl5.apple.com from 192.168.4.11 query[A] configuration.apple.com from 192.168.4.11 query[A] configuration.ls.apple.com from 192.168.4.11 query[A] crt.sectigo.com from 192.168.4.11 query[A] crt.usertrust.com from 192.168.4.11 query[A] d5ymw72datw3x.cloudfront.net from 192.168.4.11 query[A] discovery.eduroam.app from 192.168.4.11 query[A] e10499.dsce9.akamaiedge.net from 192.168.4.11 query[A] e17437.dscb.akamaiedge.net from 192.168.4.11 query[A] e4478.a.akamaiedge.net from 192.168.4.11 query[A] e673.dsce9.akamaiedge.net from 192.168.4.11 query[A] e6858.dscx.akamaiedge.net from 192.168.4.11 query[A] gateway.fe.apple-dns.net from 192.168.4.11 query[A] gateway.icloud.com from 192.168.4.11 query[A] geant.ocsp.sectigo.com from 192.168.4.11 query[A] gs-loc.apple.com from 192.168.4.11 query[A] gsp10-ssl.apple.com from 192.168.4.11 query[A] gsp64-ssl.ls.apple.com from 192.168.4.11 query[A] gsp85-ssl.ls.apple.com from 192.168.4.11 query[A] gspe1-ssl.ls.apple.com from 192.168.4.11 query[A] gspe21-ssl.ls.apple.com from 192.168.4.11 query[A] gspe35-ssl.ls.apple.com from 192.168.4.11 query[A] gsp-ssl.ls.apple.com from 192.168.4.11 query[A] identity.ess.apple.com from 192.168.4.11 query[A] init.ess.apple.com from 192.168.4.11 query[A] init.itunes.apple.com from 192.168.4.11 query[A] init-p01md.apple.com from 192.168.4.11 query[A] init.push.apple.com from 192.168.4.11 query[A] iphone-ld.apple.com from 192.168.4.11 query[A] keyvalueservice.fe.apple-dns.net from 192.168.4.11 query[A] keyvalueservice.icloud.com from 192.168.4.11 query[A] lcdn-locator.apple.com from 192.168.4.11 query[A] mesu.apple.com from 192.168.4.11 query[A] ocsp.apple.com from 192.168.4.11 query[A] ocsp.digicert.com from 192.168.4.11 query[A] ocsp-lb.apple.com.akadns.net from 192.168.4.11 query[A] ocsp.pki.goog from 192.168.4.11 query[A] ocsp.sectigo.com from 192.168.4.11 query[A] ocsp.usertrust.com from 192.168.4.11 query[A] p29-fmip.icloud.com from 192.168.4.11 query[A] p29-keyvalueservice.icloud.com from 192.168.4.11 query[A] partiality.itunes.apple.com from 192.168.4.11 query[A] pd.itunes.apple.com from 192.168.4.11 query[A] play.itunes.apple.com from 192.168.4.11 query[A] safebrowsing.googleapis.com from 192.168.4.11 query[A] setup.icloud.com from 192.168.4.11 query[A] s.mzstatic.com from 192.168.4.11 query[A] static.ess.apple.com from 192.168.4.11 query[A] su.itunes.apple.com from 192.168.4.11 query[A] time-ios.apple.com from 192.168.4.11 query[A] updates.cdn-apple.com from 192.168.4.11 query[A] www.apple.com from 192.168.4.11 query[A] www-cdn.icloud.com.akadns.net from 192.168.4.11 query[A] www.icloud.com from 192.168.4.11 query[A] xp.apple.com from 192.168.4.11 query[A] xp.itunes-apple.com.akadns.net from 192.168.4.11
I hope this is somewhat more useful. Note that Google Play and Apple AppStore are also cloud-based, but given we’re likely to be in the same region, the list may fulfil somewhat of your requirements.
With kind regards
Stefan Paetow eduroam(UK), Jisc
On Mondays and Wednesdays, I am not available between 12:00 noon and 15:00. For eduroam support, please contact us via help AT jisc.ac.uk and mark it for the eduroam team’s attention. jisc.ac.uk
From:
<cat-users-request AT lists.geant.org> on behalf of Eleanor Coultish <cat-users AT lists.geant.org>
Hi,
Apologies for cross posting with one of the Jisc groups but I thought people on here might have some additional feedback. I'm looking at improving the user experience of our onboarding/setup ssid and have hit a few issues so I was wondering how other institutions implement this.
I envisaged a user would connect to our setup ssid which most devices automatically detect as a captive portal and redirect the user to a 'sign-in' setup page. This page is an information page of how to connect
with a link to the eduroam cat tool so that users can configure their devices to connect to eduroam. The ssid has an allow/white list to various websites to give users access to the tools required to configure their devices. These are the problems I've hit
so far with this:
Android: To enable download of the geteduroam app from Google Play I have to whitelist www.google.com. With that url in the whitelist Android thinks it has Internet access so doesn't redirect to the captive portal to display the 'sign-in' setup page. Again the user would have to open a web browser and browse to the setup page.
My thinking was that the automatic redirect was a better user experience. Am I fighting a losing battle trying to use the automatic detection of the captive portal to direct users to a setup page for onboarding?
Should I just whitelist the url's that detect this and recommend going through the browser? I'm interested in how other institutions have this set up and what the user experience is?
Thanks, Eleanor Coultish
IT Services Directorate of Technology, Estates and Facilities EMAIL DISCLAIMER http://www.york.ac.uk/docs/disclaimer/email.htm To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users |
- Re: [[cat-users]] Onboarding/setup ssid, Stefan Paetow, 08/24/2022
- Re: [[cat-users]] Onboarding/setup ssid, Eleanor Coultish, 08/26/2022
- Re: [[cat-users]] Onboarding/setup ssid, Stefan Paetow, 08/26/2022
- Re: [[cat-users]] Onboarding/setup ssid, Eleanor Coultish, 08/26/2022
Archive powered by MHonArc 2.6.19.